Setup.exe

File

TrustEd aPPs dDD

This is the OutBrowse Revenyou installer which bundles offers for additional third party applications that may be unwanted and installed without consent. The file Setup.exe by TrustEd aPPs dDD has been detected as adware by 23 anti-malware scanners. The program is a setup application that uses the OutBrowse Revenyou installer. According to AVG, this software downloads additional adware offers during setup. This downloadble file is typically blocked through Google's Safe Browsing technology in Chrome web browser.
Publisher:
TrustEd aPPs dDD  (signed and verified)

Product:
File

Version:
1.9.3.0

MD5:
ea416887de44092ef90bcd2453ae4d13

SHA-1:
ba5e5a8c24fdda839ed787508e62c02c1c6f9c59

SHA-256:
b1d5646466239e0beb027fa37698f29b71bdebb1e848f7d1eea72ebea242719d

Scanner detections:
23 / 68

Status:
Adware

Explanation:
Bundles additional adware offers during download and installation using the OutBrowse installer.

Description:
This 'download manager' is also considered bundleware, a utility designed to download software (possibly legitimate or opensource) and bundle it with a number of optional offers including ad-supported utilities, toolbars, shopping comparison tools and browser extensions.

Analysis date:
12/28/2024 2:18:50 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.Outbrowse.BE
5592273

Agnitum Outpost
PUA.OutBrowse
7.1.1

AhnLab V3 Security
PUP/Win32.OutBrowse
2015.05.16

Avira AntiVirus
PUA/Outbrowse.Gen
8.3.1.6

avast!
PUP-gen [PUP]
150319-1

AVG
Potentially harmful program Downloader.GDY
2014.0.4311

Bitdefender
Application.Bundler.Outbrowse.BE
1.0.20.675

Dr.Web
infected with Trojan.OutBrowse.520
9.0.1.05190

Emsisoft Anti-Malware
Application.Bundler.Outbrowse.BE
10.0.0.5366

ESET NOD32
Win32/OutBrowse.BY potentially unwanted application
7.0.302.0

Fortinet FortiGate
Riskware/OutBrowse
5/15/2015

F-Secure
Riskware.Application.Bundler.Outbrowse
5.13.68

G Data
Application.Bundler.Outbrowse.BE
15.5.25

K7 AntiVirus
Unwanted-Program
13.203.15923

McAfee
Adware-OutBrowse.g
5600.6764

MicroWorld eScan
Application.Bundler.Outbrowse.BE
16.0.0.405

NANO AntiVirus
Trojan.Win32.OutBrowse.drieuq
0.30.24.1357

Qihoo 360 Security
HEUR/QVM30.1.Malware.Gen
1.0.0.1015

Reason Heuristics
Threat.Outbrowse.Bundler
15.5.15.10

Sophos
Generic PUA FL
4.98

SUPERAntiSpyware
Adware.OutBrowse/Variant
9874

Trend Micro House Call
Suspici.B19EDD35
7.2.135

VIPRE Antivirus
Threat.4150696
39676

File size:
1.1 MB (1,148,856 bytes)

Product version:
1.9.3.0

Copyright:
File

Original file name:
Ionic.Zip-2015May06-065229-47f45d56-f3e8-466e-8812-c71b4799464a.exe

Bundler/Installer:
OutBrowse Revenyou

Language:
Language Neutral

Common path:
C:\users\{user}\downloads\setup.exe

Digital Signature
Authority:
thawte, Inc.

Valid from:
5/4/2015 1:00:00 AM

Valid to:
1/27/2016 11:59:59 PM

Subject:
CN=TrustEd aPPs dDD, O=TrustEd aPPs dDD, L=Dublin, S=Dublin, C=IE

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
567AF1C3EE9C1411AECBBD6BFF4C9D9F

File PE Metadata
Compilation timestamp:
5/6/2015 7:52:30 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
8.0

.NET CLR dependent:
Yes

CTPH (ssdeep):
12288:BMiy4IadS4ms5I6e66fEheKhmRsbICchnP/YGZvsUnEWeL5h2yEPYNReru+ELfN1:BbSaE4mvt/76jchPQGKU5+ehzb+dmEL

Entry address:
0x75F3E

Entry point:
FF, 25, 00, 20, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
7.5753

Developed / compiled with:
Microsoft Visual C# / Basic .NET

Code size:
464 KB (475,136 bytes)

Remove Setup.exe - Powered by Reason Core Security